Trend Micro analyzed YourCyanide, a Windows CMD-based malware strain tied to the GonnaCope/Kekware/Kekpop family that blends ransomware behavior with worm-like propagation and information theft. The malware uses multilayer batch-script obfuscation and staged payload delivery via Discord, Pastebin, and a Microsoft document link, then establishes persistence through registry Run keys and copies placed in the Startup folder. It can disable Task Manager, stop security tools, enable RDP, open firewall ports, and spread through email and removable drives.
The malware also exfiltrates tokens, browser passwords, host details, and Minecraft-related credentials through the Telegram Bot API while attempting to evade analysis by checking for usernames associated with sandboxes and researchers. Trend Micro said the ransomware routine was not fully implemented at the time of analysis; instead of robust encryption, YourCyanide renamed files in common user directories and dropped ransom notes demanding $500 in Bitcoin, indicating an evolving threat that mixes disruptive and espionage-style capabilities.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Trend Micro reported 2022-05-13 as the earliest VirusTotal upload date for YourCyanide. This is the earliest explicit date tied to the specific YourCyanide variant.
Trend Micro reported 2022-05-11 as the earliest VirusTotal upload date for Kekware. This documented another successive variant in the malware family before YourCyanide appeared.
Trend Micro reported 2022-05-07 as the earliest VirusTotal upload date for Kekpop, another variant in the same CMD-based ransomware family. The upload shows the family expanding beyond GonnaCope.
Trend Micro cited 2022-04-07 as the earliest VirusTotal upload date for GonnaCope. This provides a specific dated anchor for the family’s early circulation.
Trend Micro reported that the earliest known sample in the CMD-based ransomware family, GonnaCope, was found in April 2022 by Twitter user Petrovic. This marks the earliest referenced appearance of the malware family that later included Kekpop, Kekware, and YourCyanide.
Trend Micro published an analysis of YourCyanide as the latest variant in the GonnaCope/Kekware/Kekpop family, describing its obfuscation, propagation, persistence, and information-stealing behavior. The report stated that the ransomware was still under development and that its encryption routine was not yet fully implemented.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 60 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.